remote
Application Security Engineer - BV Teck
Security Engineer
Secure and harden web applications through threat modeling, secure coding, and automated security testing, leveraging OWASP guidelines and CI/CD pipelines to protect cloud-based services.
About the role
Key Responsibilities
- Conduct threat modeling and risk assessments for new and existing applications.
- Implement secure coding practices and review code for vulnerabilities.
- Integrate automated security testing (SAST, DAST, SCA) into CI/CD pipelines.
- Perform penetration tests and remediate findings in collaboration with development teams.
- Maintain security documentation, runbooks, and incident response plans.
Requirements
- 3+ years of experience in application security or related field.
- Strong knowledge of OWASP Top 10, secure coding standards, and common web vulnerabilities.
- Hands‑on experience with SAST/DAST tools, container security, and cloud security (AWS).
- Excellent communication skills and ability to work independently in a remote environment.
Skills
owasppenetration testingaws